What information and laws are relaven to data protection?
Data Protection Act 2018
Freedom of Information Act 2000
IS09001
UKGDPR
GDPR
ICO
RICS Eletronic Data Managment - GN (Superseded to Isurv)
What is the difference between GDPR, UKGDPR and DPA2018
GDPR introduced in 2018 and applies in EU
UKGDPR is the same but applies to UK, was retained when UK left EU and is updated for full application with UK Law
i.e ICO
DPA2018 - Supplements the UKGDPR
What are the principles of GDPR
Lawfullness, transparency, accuary, proportionality, security and accountability
What is the DPA2018?
Applies to all buisnesses that hadle data, supplements UK impletmention of UKGDPR
Sets out rights of indivials:
Access
Object
Erase
Inform
Portability
Rectify
Sets out obligations of firms:
Transparency
Accountability
Proportionality
Security
Intent
Accuary
Request
Sets out defintions of data controller and proccessor
ICO duties
What is the ICO
Independant regulaotry body
Enforces DPA2018
Reviews register
Breaches must be reported to them within 72 hours
What is the Freedom of Information Act 2000
Individuals have right to access data
What are EMS?
Help companies to adhsre to DPA2018, different complexities
It includes numerous project folders
Allows collaberation
Version control
Recite issue
Drawing managment
Document retention
Issues with EMS?
Access and copyright
Secuity
Confidentiality
What is the data process?
Data created, shared, managed, stored, access, reused, archived / deleted
Examples of primary and secondary data?
Primary = reports
Secondary = BCIS, Planning, NBS and SPONS
Purpose of DPO?
Traning
Report breaches
Enforce data protection policy
Only mandatory for some organisations like public
What is BIM, and the pros and cons?
Building Information Managment System
Mandated for public sector projects to level 2 in 2016
Who are the parties inolved in GDPR
Data Subject
Data Controller
Data Processor
Data Protection Officer
Supervusory Authority
What are the penalties under GDPR and why might they occur?
Not informing of breach
Not maintaining records
Not being transpartent, proportionate, secrure, mishandling
2 Tiers as some violations are more serverve than others
€10 million, or 2% of the firm’s worldwide annual revenue
fine of up to €20 million, or 4%
What does the ICO do?
What are the entities involved